• DocumentCode
    27029
  • Title

    Effective Risk Communication for Android Apps

  • Author

    Gates, Christopher S. ; Jing Chen ; Ninghui Li ; Proctor, Robert W.

  • Author_Institution
    Dept. of Comput. Sci., Purdue Univ., West Lafayette, IN, USA
  • Volume
    11
  • Issue
    3
  • fYear
    2014
  • fDate
    May-June 2014
  • Firstpage
    252
  • Lastpage
    265
  • Abstract
    The popularity and advanced functionality of mobile devices has made them attractive targets for malicious and intrusive applications (apps). Although strong security measures are in place for most mobile systems, the area where these systems often fail is the reliance on the user to make decisions that impact the security of a device. As our prime example, Android relies on users to understand the permissions that an app is requesting and to base the installation decision on the list of permissions. Previous research has shown that this reliance on users is ineffective, as most users do not understand or consider the permission information. We propose a solution that leverages a method to assign a risk score to each app and display a summary of that information to users. Results from four experiments are reported in which we examine the effects of introducing summary risk information and how best to convey such information to a user. Our results show that the inclusion of risk-score information has significant positive effects in the selection process and can also lead to more curiosity about security-related information.
  • Keywords
    mobile computing; risk management; security of data; smart phones; Android Apps; device security; intrusive applications; malicious applications; mobile devices; mobile systems; risk communication; risk-score information; security measures; security-related information; summary risk information; Androids; Humanoid robots; Mobile communication; Privacy; Security; Smart phones; Risk communication; mobile security; usability;
  • fLanguage
    English
  • Journal_Title
    Dependable and Secure Computing, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1545-5971
  • Type

    jour

  • DOI
    10.1109/TDSC.2013.58
  • Filename
    6684532